Improper Validation of Specified Quantity in Input in Keycloak - CVE-2026-9801
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in the LDAP password policy response handling when processing a password authentication request. A remote privileged user can send a malformed LDAP password policy response to cause a denial of service.
The error terminates the Keycloak Java Virtual Machine and disrupts all realms on the affected node.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9801
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3